Russh

September 13, 2026 · View on GitHub

Crate Docs

A low-level, async SSH 2.0 client and server library for Rust / Tokio.

Russh gives you direct access to the SSH protocol: channels, authentication, key exchange, port and socket forwarding. It is written in safe Rust, uses async traits, and supports a broad range of algorithms for wide scale interoperability with real-world servers and clients.

  • Async-native - integrates directly with Tokio, AsyncRead/AsyncWrite channels
  • Broad interoperability - safe algorithms by default, with opt-in support for legacy ones
  • Safety-focused - panics, unwrap/expect and unchecked indexing are denied by default

Getting started

Add russh to your Cargo.toml, choosing a crypto backend feature (see below):

[dependencies]
russh = { version = "0.63", features = ["aws-lc-rs"] }
tokio = { version = "1", features = ["full"] }

Then have a look at the examples:

API documentation is on docs.rs

Crypto backends

Russh requires exactly one crypto backend. Enable the aws-lc-rs or ring crate feature.

# aws-lc-rs (default in most setups)
russh = { version = "0.63", features = ["aws-lc-rs"] }

# or ring (keep `flate2` and `rsa` when disabling default features)
russh = { version = "0.63", default-features = false, features = ["ring", "flate2", "rsa"] }

Supported algorithms

Russh aims for broad interoperability, so it supports both algorithms currently considered safe and a set of older ones that allow connections to older switches etc. Legacy algorithms are opt in.

Key exchange

Recommended

  • mlkem768x25519-sha256 (post-quantum hybrid)
  • curve25519-sha256, curve25519-sha256@libssh.org
  • diffie-hellman-group-exchange-sha256 (GEX)
  • diffie-hellman-group18-sha512, diffie-hellman-group17-sha512, diffie-hellman-group16-sha512, diffie-hellman-group15-sha512
  • diffie-hellman-group14-sha256
  • OpenSSH strict key exchange (Terrapin mitigation)
  • Programmatic group choice support for DH-GEX

Legacy

  • ecdh-sha2-nistp256, ecdh-sha2-nistp384, ecdh-sha2-nistp521
  • diffie-hellman-group14-sha1
  • diffie-hellman-group1-sha1
  • diffie-hellman-group-exchange-sha1 (GEX)

Ciphers

Recommended

  • chacha20-poly1305@openssh.com
  • aes256-gcm@openssh.com, aes128-gcm@openssh.com
  • aes256-ctr, aes192-ctr, aes128-ctr

Legacy

  • aes256-cbc, aes192-cbc, aes128-cbc
  • 3des-cbc (requires the des crate feature)

MACs

Recommended

  • hmac-sha2-256-etm@openssh.com, hmac-sha2-512-etm@openssh.com
  • hmac-sha2-256, hmac-sha2-512

Legacy

  • hmac-sha1-etm@openssh.com
  • hmac-sha1

Compression

  • none
  • zlib, zlib@openssh.com (requires the flate2 crate feature, on by default)

Host keys & public-key authentication

Recommended

  • ssh-ed25519
  • ecdsa-sha2-nistp256, ecdsa-sha2-nistp384, ecdsa-sha2-nistp521
  • rsa-sha2-256, rsa-sha2-512
  • ssh-rsa (SHA-1)
  • OpenSSH certificates

Authentication methods

  • publickey
  • password
  • keyboard-interactive
  • none
  • OpenSSH certificate authentication

Features

  • Local port forwarding (direct-tcpip)
  • Remote port forwarding (forward-tcpip)
  • Local UNIX socket forwarding (direct-streamlocal, client only)
  • Remote UNIX socket forwarding (forward-streamlocal)
  • AsyncRead / AsyncWrite-able channels
  • OpenSSH agent forwarding channels
  • OpenSSH keepalive request handling
  • OpenSSH server-sig-algs extension
  • PuTTY PPK key format
  • Pageant support (Windows)

Safety

Russh is built to withstand malicious/misbehaving peers.

  • deny(clippy::unwrap_used)
  • deny(clippy::expect_used)
  • deny(clippy::indexing_slicing)
  • deny(clippy::panic)

Exceptions are reviewed and justified manually.

Unsafe code

  • cryptovec uses unsafe for faster copying, initialization, and binding to native APIs.

Ecosystem

  • russh-sftp - server-side and client-side SFTP subsystem support for russh; see russh/examples/sftp_server.rs or russh/examples/sftp_client.rs.
  • async-ssh2-tokio - simple high-level API for running commands over SSH.

Adopters

  • HexPatch - A binary patcher and editor written in Rust with a terminal user interface (TUI).
    • Uses russh::client and russh_sftp::client to allow remote editing of files.
  • kartoffels - A game where you're given a potato and your job is to implement a firmware for it.
    • Uses russh::server to deliver the game, using ratatui as the rendering engine.
  • kty - The terminal for Kubernetes.
    • Uses russh::server to deliver the ratatui based TUI and russh_sftp::server to provide scp based file management.
  • lapdev - Self-hosted remote dev environment.
    • Uses russh::server to construct a proxy into your development environment.
  • medusa - A fast and secure multi-protocol honeypot.
    • Uses russh::server to be the basis of the honeypot.
  • rebels-in-the-sky - P2P terminal game about space pirates playing basketball across the galaxy.
    • Uses russh::server to deliver the game, using ratatui as the rendering engine.
  • warpgate - Smart SSH, HTTPS and MySQL bastion that requires no additional client-side software.
    • Uses russh::server in addition to russh::client as part of the smart SSH functionality.
  • Devolutions Gateway - Establish a secure entry point for internal or external segmented networks that require authorized just-in-time (JIT) access.
    • Uses russh::client for the web-based SSH client of the standalone web application.
  • Sandhole - Expose HTTP/SSH/TCP services through SSH port forwarding. A reverse proxy that just works with an OpenSSH client.
    • Uses russh::server for reverse forwarding connections, local forwarding tunnels, and the ratatui based admin interface.
  • Motor OS - A new Rust-based operating system for VMs.
    • Uses russh::server as the base for its own SSH Server.
  • Cubic VM - A lightweight command-line manager for virtual machines.
    • Uses russh::client and russh_sftp::client to access the virtual machine instances.
  • ferrissh - An async SSH CLI scraper library for network device automation in Rust.
    • Uses russh::client for SSH transport, authentication, and interactive PTY sessions.
  • Yazi - Blazing fast terminal file manager written in Rust, based on async I/O.
    • Uses russh::client to implement an async SFTP provider for remote file management.
  • GitArena - Software development platform with built-in VCS, issue tracking and code review.
    • Uses russh::server to allow Git operations over SSH.
  • Calagopus - Fast, efficient and scalable game hosting - built for everyone.
    • Uses russh::server for efficiently implementing SSH shells and SFTP file management.
  • Oryxis - Rust-native SSH client with an encrypted vault, P2P sync and an embedded terminal.
    • Uses russh::client for connections, jump hosts, SOCKS/HTTP/command proxies and SFTP.
  • react-native-ssh - Native SSH client for React Native and Expo.
    • Uses russh::client as the SSH transport implementation behind Nitro Modules bindings.

History

Russh began as a fork of Thrussh by Pierre-Étienne Meunier, originally extended to provide the SSH backend for Warpgate.

It has since been substantially reworked, and is maintained independently. Russh prioritises safety-by-default and broad algorithm interoperability. Thanks to Pierre-Étienne and the Thrussh contributors for the original foundation.

Contributors ✨

Thanks goes to these wonderful people (emoji key):

Mihir Samdarshi
Mihir Samdarshi

📖
Connor Peet
Connor Peet

💻
KVZN
KVZN

💻
Adrian Müller (DTT)
Adrian Müller (DTT)

💻
Simone Margaritelli
Simone Margaritelli

💻
Joe Grund
Joe Grund

💻
AspectUnk
AspectUnk

💻
Simão Mata
Simão Mata

💻
Mariotaku
Mariotaku

💻
yorkz1994
yorkz1994

💻
Ciprian Dorin Craciun
Ciprian Dorin Craciun

💻
Eric Milliken
Eric Milliken

💻
Swelio
Swelio

💻
Joshua Benz
Joshua Benz

💻
Jan Holthuis
Jan Holthuis

🛡️
mateuszkj
mateuszkj

💻
Saksham Mittal
Saksham Mittal

💻
Lucas Kent
Lucas Kent

💻
Raphael Druon
Raphael Druon

💻
Maya the bee
Maya the bee

💻
Milo Mirate
Milo Mirate

💻
George Hopkins
George Hopkins

💻
Åke Amcoff
Åke Amcoff

💻
Brendon Ho
Brendon Ho

💻
Samuel Ainsworth
Samuel Ainsworth

💻
Sherlock Holo
Sherlock Holo

💻
Alessandro Ricottone
Alessandro Ricottone

💻
T0b1-iOS
T0b1-iOS

💻
Shoaib Merchant
Shoaib Merchant

💻
Michael Gleason
Michael Gleason

💻
Ana Gelez
Ana Gelez

💻
Tom König
Tom König

💻
Pierre Barre
Pierre Barre

💻
Jean-Baptiste Skutnik
Jean-Baptiste Skutnik

💻
Adam Chappell
Adam Chappell

💻
Yaroslav Bolyukin
Yaroslav Bolyukin

💻
Julian
Julian

💻
Thomas Rampelberg
Thomas Rampelberg

💻
Kaleb Elwert
Kaleb Elwert

📖
Gary Guo
Gary Guo

💻
irvingouj @ Devolutions
irvingouj @ Devolutions

💻
Toni Peter
Toni Peter

💻
Nathaniel Bajo
Nathaniel Bajo

💻
Eric Rodrigues Pires
Eric Rodrigues Pires

💻
Jerome Gravel-Niquet
Jerome Gravel-Niquet

💻
Quentin Santos
Quentin Santos

📖
André Almeida
André Almeida

💻
Mattias Eriksson
Mattias Eriksson

💻
Josh McKinney
Josh McKinney

💻
citorva
citorva

💻
Eric Seppanen
Eric Seppanen

💻
Eric Seppanen
Eric Seppanen

💻
Patryk Wychowaniec
Patryk Wychowaniec

💻
@RandyMcMillan
@RandyMcMillan

💻
handewo
handewo

💻
Chris
Chris

💻
procr1337
procr1337

💻
iHsin
iHsin

💻
Uli Schlachter
Uli Schlachter

💻
Jacob Van Brunt
Jacob Van Brunt

💻
lgmugnier
lgmugnier

💻
Mingwei Samuel
Mingwei Samuel

💻
Pascal Grange
Pascal Grange

💻
wyhaya
wyhaya

💻
Philippe Laflamme
Philippe Laflamme

💻
Tom
Tom

💻
vzex
vzex

💻
Kenny Root
Kenny Root

💻
Môshe van der Sterre
Môshe van der Sterre

💻
Lucy
Lucy

💻
Mark Bundschuh
Mark Bundschuh

💻
tayu0110
tayu0110

💻
Roger Knecht
Roger Knecht

💻
Guilherme Fontes
Guilherme Fontes

💻
Lyn
Lyn

💻
Mota-Link
Mota-Link

💻
Mika Cohen
Mika Cohen

💻
François Bernier
François Bernier

💻
kpcyrd
kpcyrd

💻
Corey Leavitt
Corey Leavitt

💻
wi-adam
wi-adam

💻
Artem Medvedev
Artem Medvedev

💻
ztbh
ztbh

💻
Moder Steven
Moder Steven

💻
Jeongkyu Shin
Jeongkyu Shin

💻
PokAhonTAS911
PokAhonTAS911

💻
ayamir
ayamir

💻
Luiz Ribeiro
Luiz Ribeiro

💻
biao29
biao29

💻
Georg von Zengen
Georg von Zengen

💻
tluyben
tluyben

💻
Marko Vejnovic
Marko Vejnovic

💻

This project follows the all-contributors specification. Contributions of any kind welcome!